Section 43A and the 2011 Rules 3-8
In 2011, delegated legislation made under section 43a of the IT Act created a data privacy regime. However, the rules are perhaps ultra vires, apply only to very strict definitions of sensitive data, and provide rights of action only to the “providers of data”.
Rule 8: Reasonable Security
“Such security practices and standards have a comprehensive documented info sec program and info sec policies that contain managerial, technical, operational, and physical security control measures that are commensurate with the info assets being protected with the nature of business.”
“In the event of an info sec breach, the body corporate … shall be required to demonstrate [to agency] that they have implemented security control measures as per their documented info sec program and policies.”
Burden of proof in R8 likely does not override 43A’s standard of negligence. But does have separate obligation to demonstrate security.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Bhimesh
8 months agorhyst1921
8 months, 1 week ago